Privacy Policy
Coreware AI, LLC · Effective August 29, 2026 · Last updated August 29, 2026
FFLAI — an AI-powered content generation platform for Federal Firearms Licensees
This Privacy Policy explains how Coreware AI, LLC ("Company," "we," "us," or "our") collects, uses, discloses, and safeguards information in connection with FFLAI (the "Service"). It is part of, and incorporated by reference into, the Terms of Service. Capitalized terms not defined here have the meanings in the Terms of Service.
Table of Contents — Privacy Policy
1. Introduction and Scope
2. Information We Collect
3. How We Use Information
4. AI Processing and Third-Party Model Providers
5. Customer Data Processed on Your Behalf; Roles
6. Cookies and Tracking Technologies
7. How and With Whom We Share Information
8. Data Retention and Deletion
9. Security
10. Data Breach Notification Posture
11. Your Rights and Choices
12. California, Virginia, Colorado, Connecticut, Utah, and Other State Privacy Rights
13. Do Not Track / Global Privacy Control
14. Children's Privacy
15. International Data Transfers
16. Third-Party Links, Services, and Integrations
17. Changes to This Privacy Policy
18. California "Shine the Light" Disclosure
19. Data Processing Addendum (DPA) Summary and Reference
20. Contact
21. Automated Decision-Making Disclosure
22. Sensitive Personal Information; Regulated Data Restrictions
1. Introduction and Scope
1.1 Purpose. This Privacy Policy applies to Personal Data processed by Coreware AI, LLC ("Company") in connection with FFLAI — an AI-powered content generation platform for Federal Firearms Licensees (the "Service") — the coreware.com, and related communications and marketing.
1.2 Who This Applies To. This Privacy Policy applies to (a) customers and authorized users of the Service (owners, principals, employees, contractors of FFLs and other subscribed businesses); (b) visitors to our website; and (c) prospects who contact us. This Privacy Policy does not describe how our customers use Personal Data of their own end customers; for that, see the customer's own privacy policy.
1.3 Not Legal Advice. Nothing in this Privacy Policy is legal advice. This Privacy Policy describes our practices, not yours. Your compliance with privacy law is your responsibility (see Section 5 of the Terms of Service).
2. Information We Collect
We collect the following categories of information. "You" in this Section 2 means the human individual interacting with the Service (an account owner, admin user, or invited user).
2.1 Account and Contact Information.
Name, business name, business role, email address, phone number, mailing address, and password credentials; and optional profile information such as your FFL number (if you choose to provide it), your state, and your area of business (retail dealer, gunsmith, range, etc.).
2.2 Connected Integration Data.
When you connect a Third-Party Platform to the Service (POS, e-bound-book, calendar, marketing platform, ad network, social media account), we receive the OAuth tokens, API credentials, and related data required to operate the integration on your behalf, together with the data returned by the Third-Party Platform. Depending on your configuration, this may include inventory records, product metadata, transaction summaries, event calendars, customer lists you have designated for marketing purposes, ad-account metadata, post history, and analytics data. YOU CONTROL WHAT DATA IS AVAILABLE TO US VIA THE PERMISSIONS YOU GRANT WITHIN EACH THIRD-PARTY PLATFORM; YOU SHOULD NOT GRANT ACCESS TO REGULATED RECORDS (SUCH AS BOUND BOOK / A&D ENTRIES OR FORM 4473 IMAGES) UNLESS THE SERVICE'S DOCUMENTATION FOR THAT INTEGRATION EXPRESSLY SUPPORTS IT.
2.3 Inputs and Outputs.
The prompts, uploads, files, images, references, and other content you submit to the Service ("Inputs") and the content the Service generates in response ("Outputs"), together with metadata about them (timestamps, action IDs, model used, evaluation scores).
2.4 Usage and Device Data.
Log files; IP address; approximate geolocation derived from IP; browser type and version; operating system and device identifiers; time zone; language; referring/exit URLs; pages viewed; features used; clicks, scrolls, and other in-product events; performance metrics; and error and diagnostic data.
2.5 Payment Information.
Payment is processed by a third-party payment processor. We do not store full payment-card numbers on our systems. We receive a token, the last four digits of the card, card type, expiration month/year, billing name, and billing address, sufficient to identify the payment method and reconcile transactions.
2.6 Communications.
Content of your communications with our sales, support, and legal teams (including email, chat, and voice calls that are recorded with notice), and your subscription and communication preferences.
2.7 Cookies and Tracking.
See Section 6 for our use of cookies, pixels, SDKs, session-replay tools, and similar technologies on the Service and our website.
2.8 Marketing and Prospect Data.
For prospects and website visitors, we may collect information from public sources, business-data providers, and events (e.g., industry trade shows, webinars). This includes business contact information and, where publicly available, FFL type and license status.
2.9 Information We Do Not Intentionally Collect.
We do not intentionally collect: government-issued identifiers (SSN, driver's license number); background-check content; complete Form 4473 fields; Bound Book / A&D Record entries; NICS reference numbers; protected health information subject to HIPAA; or payment-card primary account numbers. If you upload such information as part of an Input or via an integration, you do so in breach of the Terms of Service (see § 8) and at your own risk; we will treat it as Confidential Information and take commercially reasonable steps to purge or restrict access on discovery.
3. How We Use Information
We process information for the following purposes:
Provide, operate, and maintain the Service, including account creation, authentication, personalization, and delivery of Outputs;
Route prompts to appropriate AI Systems and generate Outputs;
Bill for the Service and administer subscriptions;
Provide customer support and respond to inquiries;
Monitor, secure, and troubleshoot the Service; detect and prevent abuse, fraud, and unauthorized access; and enforce the Terms of Service;
Improve the Service, including product analytics, quality-assurance review of Outputs, safety review, evaluation, prompt-template refinement, and (where you have not opted out) model fine-tuning;
Comply with law, regulatory obligations, and lawful requests from government authorities;
Send transactional communications (e.g., account, billing, security) and, where permitted, marketing communications about the Service; and
Any other purpose disclosed to you at the time of collection or with your consent.
3.1 Legal Bases (Where Applicable). Where your Personal Data is subject to laws requiring a specified legal basis for processing, we rely on: performance of the contract with you (Terms of Service); our legitimate interests in operating and improving the Service, preventing abuse, and marketing (balanced against your rights); your consent (which you may withdraw); and compliance with legal obligations.
4. AI Processing and Third-Party Model Providers
4.1 Sub-Processors. The Service uses third-party AI model providers as sub-processors to generate Outputs. Depending on the requested action and our routing policy, an Input (and, in some cases, portions of Customer Data) is transmitted over the internet to one or more of these providers for inference. Providers may include large language model providers and image-generation providers. Our current list of sub-processors is available at coreware.com/subprocessors.
4.2 Retention by Providers. Sub-processors handle Inputs and Outputs under their own privacy and security terms, which typically include limited retention for abuse-prevention and, in most cases, do not train their foundation models on API traffic. Retention periods and practices are set by the provider and are subject to change. We disclaim any warranty regarding sub-processor practices.
4.3 Do Not Submit Sensitive or Regulated Content. YOU SHOULD NOT SUBMIT SENSITIVE PERSONAL DATA (SUCH AS GOVERNMENT IDENTIFIERS, HEALTH INFORMATION, OR PAYMENT-CARD PRIMARY ACCOUNT NUMBERS), COMPLETE REGULATED RECORDS (SUCH AS FORM 4473 IMAGES OR BOUND BOOK / A&D ENTRIES), NICS REFERENCE NUMBERS, PRIVILEGED LEGAL COMMUNICATIONS, OR TRADE SECRETS TO THE SERVICE. IF YOU DO, YOU DO SO AT YOUR OWN RISK AND IN BREACH OF THE TERMS OF SERVICE.
4.4 Training. If you do not opt out (see § 10 of the Terms), we may use Inputs and Outputs to train, fine-tune, and evaluate our own models and prompt templates. We do not sell your Personal Data. We do not train third-party foundation models on your Inputs and Outputs except through the provider-specific fine-tuning or evaluation arrangements we control.
5. Customer Data Processed on Your Behalf; Roles
5.1 Roles. When our customer (a business, typically an FFL) is subject to a privacy law that assigns responsibility for Personal Data of the business's end customers, the business acts as the "controller," "business," or equivalent responsible party, and Company acts as its "processor" or "service provider," processing Personal Data on the business's documented instructions in the Terms of Service, this Privacy Policy, and any DPA.
5.2 What We Do With Customer-Provided End-Customer Data. We use Customer Data solely to provide, secure, and improve the Service and as otherwise described in the Terms of Service. We do not sell Customer Data. We do not share Customer Data with third parties except sub-processors bound by confidentiality and data-protection commitments, and as otherwise required by law.
5.3 Requests From End Customers. Requests from an end customer of one of our business customers (for example, an individual who buys firearms from an FFL that uses the Service) should be directed to that business, not to us. We will forward such requests to the applicable business customer and will reasonably assist the business in responding as required by law.
6. Cookies and Tracking Technologies
6.1 Types. We and our service providers use cookies, web beacons, pixels, SDKs, and similar technologies for: strictly necessary purposes (session, authentication, load balancing); functionality (remembering preferences); analytics (measuring usage and diagnostics); and, on our marketing pages, advertising and attribution.
6.2 Consent. Where required by applicable law, we obtain consent before setting non-essential cookies. Where consent is not required, non-essential cookies are set based on our legitimate interest.
6.3 Managing Cookies. Most browsers allow you to block or delete cookies. Blocking essential cookies may impair the Service.
6.4 Session Replay. We may use session-replay tools on our marketing pages and, with your consent, in the Service for support and quality purposes. Where used, these tools capture user interactions with the interface; they are not used to capture keystrokes in sensitive fields (e.g., password).
7. How and With Whom We Share Information
7.1 We Do Not Sell Personal Data. We do not sell Personal Data, and we do not "share" Personal Data for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA and comparable state laws.
7.2 Categories of Recipients. We disclose information as follows:
Sub-processors and service providers that host, secure, deliver, analyze, or support the Service (e.g., cloud hosting, AI model providers, database providers, email/SMS providers, analytics providers, error-monitoring, customer support platform, payment processor). These recipients act under contractual confidentiality and data-protection commitments;
Third-Party Platforms you connect, in order to operate the integration;
Corporate affiliates, under commitments consistent with this Privacy Policy;
Professional advisors (lawyers, auditors, accountants);
Government authorities and other parties where required by law, valid legal process (subpoena, court order), or to protect the rights, property, or safety of Company, our customers, our users, or others; and
In connection with a merger, acquisition, financing, reorganization, sale of assets, or similar corporate transaction, subject to standard confidentiality protections.
8. Data Retention and Deletion
8.1 Retention. We retain Personal Data and Customer Data for as long as your account is active and thereafter as necessary to: (a) provide the Service and support; (b) comply with legal, tax, and accounting obligations; (c) resolve disputes and enforce agreements; (d) support abuse-prevention and security investigations; and (e) as otherwise permitted by law.
8.2 Backups and Cache. Data may remain in backups and caches for a commercially reasonable period after deletion from the primary systems.
8.3 De-identified Data. We may retain de-identified and/or aggregated data indefinitely.
8.4 Post-Termination Export. See Section 19.5 of the Terms for post-termination export.
9. Security
9.1 Measures. We use commercially reasonable administrative, technical, and physical safeguards designed to protect information, including: encryption in transit; encryption at rest for stored data; role-based access controls and least-privilege access; multi-factor authentication for internal administrative access; logging and monitoring; vulnerability management; incident-response procedures; and vendor management for sub-processors.
9.2 NO ABSOLUTE SECURITY. NO SYSTEM CONNECTED TO THE INTERNET IS PERFECTLY SECURE. WE CANNOT AND DO NOT GUARANTEE THAT INFORMATION WILL NOT BE ACCESSED, DISCLOSED, ALTERED, OR DESTROYED BY BREACH OF ANY OF OUR SAFEGUARDS. YOU ACKNOWLEDGE THAT USING THE SERVICE INVOLVES AN INHERENT RISK OF BREACH, AND YOU ACCEPT THAT RISK.
9.3 Your Responsibility. You are responsible for maintaining the security of your credentials, for the security of devices you use to access the Service, and for the acts of your personnel (see § 20 of the Terms).
10. Data Breach Notification Posture
10.1 Notice. If we determine that a security incident has affected your Personal Data in a manner requiring notification under applicable law, we will notify you without undue delay and as required by that law, using the contact information on your account. You are responsible for keeping your contact information current.
10.2 Cooperation. We will reasonably cooperate with your investigation and any notification obligations you have to your end customers. Nothing in this section is an admission of liability.
11. Your Rights and Choices
11.1 Access, Correction, Deletion, and Portability. Subject to applicable law and identity verification, you may request to: access the Personal Data we hold about you; correct inaccurate Personal Data; delete Personal Data; obtain a portable copy of Personal Data; restrict or object to certain processing; and withdraw consent where processing is based on consent.
11.2 How to Exercise. Submit a request to aaron.weinstein@coreware.com with sufficient detail for us to identify your account and the request. We may request additional information to verify identity. We will respond within the time required by applicable law (typically 30–45 days, extendable as permitted).
11.3 Marketing Choices. You may opt out of promotional email by using the unsubscribe link in the message or by contacting us. Transactional messages (billing, security, service) will continue.
11.4 No Discrimination / No Retaliation. We will not discriminate or retaliate against you for exercising your privacy rights.
12. California, Virginia, Colorado, Connecticut, Utah, and Other State Privacy Rights
12.1 California (CCPA/CPRA).
If you are a California resident, you have the rights described in Section 11 as well as the right to know the categories and specific pieces of Personal Information we have collected about you; the categories of sources; the business or commercial purposes for collecting; and the categories of third parties with whom we share Personal Information. You have the right to request deletion and correction, and the right to limit the use of "sensitive personal information" as defined by CPRA. We do not sell Personal Information, and we do not "share" Personal Information for cross-context behavioral advertising, as those terms are defined by the CCPA/CPRA. You may designate an authorized agent to submit a request on your behalf, subject to verification. Submit requests to aaron.weinstein@coreware.com.
12.2 Categories Under CCPA/CPRA.
In the preceding twelve (12) months, we have collected the following categories of Personal Information: identifiers; customer records; commercial information; internet or other electronic network activity; geolocation (approximate, from IP); professional or employment-related information; and inferences drawn from the foregoing. We have collected these categories from you, your organization, your devices, cookies and tracking technologies, sub-processors, and public and third-party business sources. We have disclosed these categories for the business purposes described in Section 3 and to the categories of recipients described in Section 7.
12.3 Virginia, Colorado, Connecticut, Utah, and Other State Laws.
If you are a resident of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Iowa (ICDPA), Delaware (DPDPA), New Jersey (NJDPA), Tennessee (TIPA), or another state with a comparable consumer-privacy law, you have rights that substantially parallel those described in Section 11 (access, correction, deletion, portability, opt-out of certain processing, and appeal of denied requests). To submit a request or appeal, contact us at aaron.weinstein@coreware.com.
12.4 Sensitive Data.
We do not use sensitive personal data for advertising or for cross-context behavioral advertising. We do not knowingly process sensitive personal data of a consumer without a lawful basis; if you provide sensitive data through an Input in violation of § 8 of the Terms, we will handle it in accordance with our security measures and applicable law.
13. Do Not Track / Global Privacy Control
13.1 We honor Global Privacy Control ("GPC") signals from supported browsers as an opt-out signal for the sale or "sharing" of Personal Information under CCPA/CPRA and comparable state laws, to the extent required. Because we do not sell or "share" Personal Information, a GPC signal will not materially change our processing. We do not currently respond to legacy "Do Not Track" browser headers.
14. Children's Privacy
14.1 The Service is not directed to individuals under twenty-one (21) years of age and, in any event, not to children under thirteen (13) years of age. We do not knowingly collect Personal Data from anyone under 13 (or under 16 where applicable law imposes that limit) or from anyone under 21 as a matter of Service policy. If you believe a minor has provided Personal Data to us, contact aaron.weinstein@coreware.com and we will investigate and, if confirmed, delete the data.
15. International Data Transfers
15.1 The Service is hosted in the United States. If you access the Service from outside the United States, you consent to the transfer, processing, and storage of your information in the United States and in other countries where our sub-processors operate. Data-protection laws in these countries may differ from those of your country. Where required, we implement appropriate safeguards for cross-border transfers (such as Standard Contractual Clauses).
16. Third-Party Links, Services, and Integrations
16.1 The Service may contain links to, and integrations with, Third-Party Platforms. Those platforms have their own privacy practices, over which we have no control. This Privacy Policy does not apply to any Third-Party Platform. Review each Third-Party Platform's privacy policy before using it.
17. Changes to This Privacy Policy
17.1 We may update this Privacy Policy from time to time. Material changes will be posted with a revised "Last Updated" date at coreware.com/legal and, where reasonably practicable, provided by email or in-product notice. Continued use of the Service after the effective date of a change indicates acceptance.
18. California "Shine the Light" Disclosure
18.1 California Civil Code § 1798.83 permits California residents to request a notice disclosing the categories of Personal Information we shared with third parties for those third parties' direct-marketing purposes during the preceding calendar year. We do not share Personal Information with third parties for their direct-marketing purposes. To submit a request, contact aaron.weinstein@coreware.com.
19. Data Processing Addendum (DPA) Summary and Reference
19.1 DPA Availability. For customers subject to laws requiring a data-processing agreement (e.g., GDPR, UK GDPR, CCPA/CPRA service-provider provisions), a Data Processing Addendum is available at coreware.com/dpa or by request to aaron.weinstein@coreware.com. The DPA sets out the parties' roles, processing details, security commitments, sub-processor procedures, transfer mechanisms, and audit rights.
19.2 Precedence. To the extent an executed DPA conflicts with this Privacy Policy in respect of Customer Data processed on your behalf, the DPA controls.
20. Contact
20.1 Privacy Contact. Questions or requests regarding this Privacy Policy may be sent to:
Coreware AI, LLC — Attn: Privacy
215 NW 24th St, Suite 700, Miami, FL 33127
aaron.weinstein@coreware.com
21. Automated Decision-Making Disclosure
21.1 Nature of AI Automation. The Service uses automated processing (AI Systems) to generate content in response to your Inputs. This automation is assistive: it produces drafts and suggestions for you to review, and it does not make decisions that produce legal or similarly significant effects concerning any natural person on our behalf. You are the decision-maker with respect to whether and how to use an Output.
21.2 Content-Moderation and Abuse-Prevention Automation. To protect the Service, we use automated systems to detect and prevent abuse (e.g., prompts that violate § 8 of the Terms). These systems may cause the Service to decline to generate an Output. You can contact aaron.weinstein@coreware.com to seek human review of a declined request.
22. Sensitive Personal Information; Regulated Data Restrictions
22.1 What Not To Submit. As stated in § 8 of the Terms and § 4.3 of this Privacy Policy, do not submit to the Service: Social Security numbers or other government identifiers; complete Form 4473 fields or images; Bound Book / A&D Record entries; NICS reference numbers; background-check content; protected health information; payment-card primary account numbers; or any other sensitive or regulated data, except through channels the Service expressly designates for that purpose. Any such submission is at your risk and in violation of the Terms.
— End of Document —
© 2026 Coreware AI, LLC. All rights reserved.